Threat Cluster 47[.]109[.]196[.]181

Dual-vector threat staging operation distributing Android accessibility spyware and remote access trojans (harvesting victim screen telemetry, keystrokes, and accessibility events) alongside weaponized Linux local privilege escalation exploits (Dirty COW / efull) and PHP upload webshells.

Threat Cluster 47[.]109[.]196[.]181

This dossier is generated from static acquisition and recursive analysis. Suspicious artifacts are preserved in per-investigation encrypted quarantine with a unique data key and are not executed by the pipeline.

Evidence Coverage

MetricValue
Acquired artifacts37
Text artifacts18
Binary/container artifacts19
Unique acquired/decoded layers analyzed180
Maximum recursive depth reached2
Archive/disk-image entries extracted313
PE candidates statically identified0
Credential/key/token findings1
Recursive queue exhausted within configured limitsYes

Motivation & Objectives

Strategic Motivation

Dual-vector threat staging operation distributing Android accessibility spyware and remote access trojans (harvesting victim screen telemetry, keystrokes, and accessibility events) alongside weaponized Linux local privilege escalation exploits (Dirty COW / efull) and PHP upload webshells.

Operational Objectives

  • Mobile Spyware Distribution: Hosting and updating Android APK and Dalvik (.dex) implants equipped with accessibility service (无障碍) logging and automated screenshot exfiltration.
  • Host Privilege Escalation: Staging weaponized Linux kernel root exploits (Dirty COW, efull, dcrun) and audit scripts to elevate privileges and defend staging infrastructure.
  • Web Infrastructure Staging: Operationalizing PHP webshells and upload handlers for dynamic remote payload staging and command execution.
  • Defense Evasion: Impairing telemetry monitoring and antivirus/EDR real-time scanning.
  • Credential Access: Harvesting plaintext passwords, API keys, and environment tokens from exposed files.

Inferred Target Profile

  • Mobile Endpoints (Android Device Users & Mobile Banking/Messaging Portals)
  • Enterprise Linux Web Servers & Staging Infrastructure

Key Operational Findings

  • HTML Smuggling / In-memory file synthesis
  • Linux Kernel Privilege Escalation / Local Root Exploits
  • Android Accessibility Service (无障碍) Abuse & Telemetry Exfiltration
  • Automated Screenshot Capture & Exfiltration

Credentials, Keys & Tokens (Redacted)

RiskTypeRedacted ValueSource / Layer
HighGeneric Hardcoded Secret[REDACTED_HARDCODED_SECRET]qdw.apk / L1 (zip-entry:assets/modules/npm/cheerio.js)

Verified Indicators

TypeDefanged Value / HashContextConfidence
Investigated Host47[.]109[.]196[.]181User-supplied investigated hostHigh (observed)
Service Endpoint47[.]109[.]196[.]181:80User-supplied investigated HTTP(S) serviceHigh (observed)
SHA-256 Hashd8dd09b01eb4e363d88ff53c0aace04c39dbea822b7adba7a883970abbf72a77Acquired artifact: 855c3273-85d3-4db0-a04b-a164dcf8b613_sp=r (Linux ELF Binary)High (computed)
SHA-256 Hash1f325cef63653aae070e74e84b7896796d7513c640639b6e2a2c2942e4116a42Acquired artifact: dc1 (Linux ELF Binary)High (computed)
SHA-256 Hash34966d1db7c916440b4c3b6f74c1237cb0de55818309dfca9052290cb15df4fdAcquired artifact: efull (Linux ELF Binary)High (computed)
SHA-256 Hash8d26e7b51cfcb45330c22d8ddc3092423d573f6f6dacc99fa948c3e28a814c1aAcquired artifact: exploit.py (Plain/Textual Content)High (computed)
SHA-256 Hash12c2d06affb4aec5d20321af3fbbea7c4c68dfeb8be6dae606def63559dede94Acquired artifact: fh.dex (Android Dalvik Executable (DEX))High (computed)
SHA-256 Hash8dcef4460a4ac5e774b2c50cf5f72921f3ce3d1a10f115be40455ae26bc7c469Acquired artifact: fhhotversion.txt (Plain/Textual Content)High (computed)
SHA-256 Hash2e2d5a551250572a2117a4ef477acb5c5318e6886208ed814acff287328c4a33Acquired artifact: linux-exploit-suggester.sh (Plain/Textual Content)High (computed)
SHA-256 Hash563a2aaa61e13684690be7e75d54a478bbc619f3aec3fda77094da13f6ca4cbcAcquired artifact: qdw.apk (ZIP-compatible Archive)High (computed)
SHA-256 Hash8700462941d46269f54459fdd6be3a75ee3ba89f42ff5b22837e08fcec47b73fAcquired artifact: qdwdex.dex (Android Dalvik Executable (DEX))High (computed)
SHA-256 Hashdb38455f4d6fc73c8135322369c1b49c50eb1c1d3a2d2fef95048ca37308ebe3Acquired artifact: qdwdex.sha256 (Plain/Textual Content)High (computed)
SHA-256 Hash2788952ebe85f64faab393233d024d3403c502f9bb4974f39e16b1f2e70f3a0fAcquired artifact: qdwhotversion.txt (Plain/Textual Content)High (computed)
SHA-256 Hash59854984853104df5c353e2f681a15fc7924742f9a2e468c29af248dce45ce03Acquired artifact: qdwversion.txt (Plain/Textual Content)High (computed)
SHA-256 Hash00a1fb2812f96b1c951e67bf3e2d56ec2617fa0a32b53ce94fb2e83fb2d7f419Acquired artifact: screenshot_1779509068742_upload.jpg (JPEG Image)High (computed)
SHA-256 Hash7e57ff860acec75bb45c4f68f102da125397ca5648653313446fdceba0f24362Acquired artifact: screenshot_1779509082560_upload.jpg (JPEG Image)High (computed)
SHA-256 Hash56c0a46ce12cdadc6e5f2805dffd11a34109282cf694890eacf8a3e564a4a80eAcquired artifact: screenshot_1779509847953_upload.jpg (JPEG Image)High (computed)
SHA-256 Hash291d1e82991ae95e371a23b379c737d6e755683fc03d9b06994538438f7cb40dAcquired artifact: screenshot_1779509865344_upload.jpg (JPEG Image)High (computed)
SHA-256 Hashb694a50adb81ca880c47a6919454f8c5b98fc4d083c8124d1f0a92988785a1a4Acquired artifact: screenshot_1779509942356_upload.jpg (JPEG Image)High (computed)
SHA-256 Hash54927582ae30c80bf5147e3ba803415079e1c94c810dd520c9cfd35d69480e77Acquired artifact: screenshot_1779534039610_upload.jpg (JPEG Image)High (computed)
SHA-256 Hashadffc9cfa36d3927dbd2d11046a6d3eb3f434bfbd4a17d6a0355e4f12c259e48Acquired artifact: shell.php (Plain/Textual Content)High (computed)
SHA-256 Hash397c8f12e7340fedf35a8d20907762de0ccdbf971d0447585a03e945ae92f9d4Acquired artifact: update (Linux ELF Binary)High (computed)
SHA-256 Hash12079d77cb3633c6a22c4c8722fb82146dd78072d99a4fa60bdb0dc6205d2680Acquired artifact: upload.php (Raw Data / Unknown Format)High (computed)
SHA-256 Hash11e2f85f9eecd2472eb37290defaeacbbf3b6837edd07d4d7219df368fe8d60cAcquired artifact: wuzhangai_1779509068742.txt (Plain/Textual Content)High (computed)
SHA-256 Hashb79f374cd9c50c966214fdc0bdecc61af76ca7b75fd2c30a86bf22097bce36a1Acquired artifact: wuzhangai_1779509082560.txt (Raw Data / Unknown Format)High (computed)
SHA-256 Hash994c5d059318355ea815cdd5cc70aec9bac6d70c96fa1504aa5589bc03244ed7Acquired artifact: wuzhangai_1779509847953.txt (Plain/Textual Content)High (computed)
SHA-256 Hash20fb8690c0fa5b01143f3664634aae73cc62530e75d602b079372a6818787f0aAcquired artifact: wuzhangai_1779509865344.txt (Raw Data / Unknown Format)High (computed)
SHA-256 Hash22a2caa348308c401049d67dc21b7e5c93da167495db2c467b387843ca8c5d52Acquired artifact: wuzhangai_1779509942356.txt (Plain/Textual Content)High (computed)
SHA-256 Hash2ace47f2b47e6cad2b2d8883c318561199031faf951d948f9794197915ea08ebAcquired artifact: wuzhangai_1779534039610.txt (Plain/Textual Content)High (computed)
SHA-256 Hashd99a7b458c51243bd2e554272f413a3d368525b04de505ebca98843b35fb63e3Acquired artifact: yh.apk (ZIP-compatible Archive)High (computed)
SHA-256 Hashe9bdd0010b8ad74b752f1240bbd05f648768ed98fdcb670d3377f7d04f9b3509Acquired artifact: yhdex.dex (Android Dalvik Executable (DEX))High (computed)
SHA-256 Hashf69ee8d3f2c741ce497327143af238581421573c4cf387ccbb633918033cae51Acquired artifact: yhdex.sha256 (Plain/Textual Content)High (computed)
SHA-256 Hash28cb8f1299bee499c8fd2b3b88e3fbae260a2b86b7310329fec85cf834954b8fAcquired artifact: yhhotversion.txt (Plain/Textual Content)High (computed)
SHA-256 Hash92521fc3cbd964bdc9f584a991b89fddaa5754ed1cc96d6d42445338669c1305Acquired artifact: yhversion.txt (Plain/Textual Content)High (computed)
URLhxxps://github.com/xeloxaObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://www[.]kernel[.]org/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/mzet-Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://isec[.]pl/vulnerabilities/isec-0021-uselib.txtObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20111103042904/hxxp://tarantula[.]by[.]ru/localroot/2.6.x/elflblObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20111103042904/hxxp://tarantula[.]by[.]ru/localroot/2.6.x/h00lyshitObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://xorl[.]wordpress[.]com/2009/07/16/cve-2009-1895-linux-kernel-per_clear_on_setid-personality-bypass/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gitlab[.]com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/9435.tgzObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gitlab[.]com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/9436.tgzObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gitlab[.]com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/9641.tar.gzObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gitlab[.]com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/9574.tgzObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://blog[.]cr0[.]org/2009/08/cve-2009-2698-udpsendmsg-vulnerability.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/Kabot/Unix-Privilege-Escalation-Exploits-Pack/raw/master/2009/CVE-2009-2698/katon.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20111103042904/hxxp://tarantula[.]by[.]ru/localroot/2.6.x/kmod2Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20111103042904/hxxp://tarantula[.]by[.]ru/localroot/2.6.x/ptrace-kmodObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192641/hxxps://www[.]kernel-exploits[.]com/media/ptrace_kmod2-64Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://jon[.]oberheide[.]org/blog/2010/04/10/reiserfs-reiserfs_priv-vulnerability/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://jon[.]oberheide[.]org/files/team-edward.pyObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192641/hxxps://www[.]kernel-exploits[.]com/media/can_bcmObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]securityfocus[.]com/archive/1/514379Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://web[.]archive[.]org/web/20101020044048/hxxp://www[.]vsecurity[.]com/download/tools/linux-rds-exploit.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192641/hxxps://www[.]kernel-exploits[.]com/media/rdsObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192641/hxxps://www[.]kernel-exploits[.]com/media/rds64Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://web[.]archive[.]org/web/20160602192631/hxxps://www[.]kernel-exploits[.]com/media/half-nelson3Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://git[.]zx2c4[.]com/CVE-2012-0056/about/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://git[.]zx2c4[.]com/CVE-2012-0056/plain/mempodipper.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192631/hxxps://www[.]kernel-exploits[.]com/media/memodipperObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192631/hxxps://www[.]kernel-exploits[.]com/media/memodipper64Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://vulnfactory[.]org/exploits/full-nelson.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192631/hxxps://www[.]kernel-exploits[.]com/media/full-nelsonObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192631/hxxps://www[.]kernel-exploits[.]com/media/full-nelson64Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://stealth[.]openwall[.]net/xSports/clown-newuser.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://lwn[.]net/Articles/543273/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://timetobleed[.]com/a-closer-look-at-a-recent-privilege-escalation-bug-in-linux-cve-2013-2094/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192631/hxxps://www[.]kernel-exploits[.]com/media/perf_sweventObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192631/hxxps://www[.]kernel-exploits[.]com/media/perf_swevent64Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://cyseclabs[.]com/exploits/vnik_v1.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]openwall[.]com/lists/oss-security/2013/04/29/1Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://blog[.]includesecurity[.]com/2014/03/exploit-CVE-2014-0038-x32-recvmmsg-kernel-vulnerablity.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192631/hxxps://www[.]kernel-exploits[.]com/media/timeoutpwn64Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://blog[.]includesecurity[.]com/2014/06/exploit-walkthrough-cve-2014-0196-pty-kernel-race-condition.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://cyseclabs[.]com/page?n=02012016Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]openwall[.]com/lists/oss-security/2014/06/10/4Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]openwall[.]com/lists/oss-security/2014/07/08/16Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://cyseclabs[.]com/page?n=01102015Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://labs[.]bromium[.]com/2015/02/02/exploiting-badiret-vulnerability-cve-2014-9322-linux-kernel-privilege-escalation/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://site.pi3[.]com[.]pl/exp/p_cve-2014-9322.tar.gzObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]openwall[.]com/lists/oss-security/2015/08/04/8Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://seclists[.]org/oss-sec/2015/q2/717Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192631/hxxps://www[.]kernel-exploits[.]com/media/ofs_32Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://web[.]archive[.]org/web/20160602192631/hxxps://www[.]kernel-exploits[.]com/media/ofs_64Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]halfdog[.]net/Security/2015/UserNamespaceOverlayfsSetuidWriteExec/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://perception-point[.]io/2016/01/14/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://cyseclabs[.]com/blog/cve-2016-0728-poc-not-workingObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://xairy[.]github[.]io/blog/2016/cve-2016-2384Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/xairy/kernel-exploits/master/CVE-2016-2384/poc.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gitlab[.]com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/40053.zipObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://bugs[.]chromium[.]org/p/project-zero/issues/detail?id=808Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gitlab[.]com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/39772.zipObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/dirtycow/dirtycow.github.io/wiki/VulnerabilityDetailsObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://access[.]redhat[.]com/sites/default/files/rh-cve-2016-5195_5.shObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://www[.]exploit-db[.]com/download/40847Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]openwall[.]com/lists/oss-security/2016/12/06/1Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/rapid7/metasploit-framework/master/data/exploits/CVE-2016-8655/chocobo_rootObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/xairy/kernel-exploits/tree/master/CVE-2016-9793Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/xairy/kernel-exploits/master/CVE-2016-9793/poc.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]openwall[.]com/lists/oss-security/2017/02/22/3Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://googleprojectzero[.]blogspot[.]com/2017/05/exploiting-linux-kernel-via-packet.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/xairy/kernel-exploits/master/CVE-2017-7308/poc.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/bcoles/kernel-exploits/master/CVE-2017-7308/poc.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/rapid7/metasploit-framework/master/data/exploits/cve-2017-7308/exploitObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://ricklarabee[.]blogspot[.]com/2018/07/ebpf-and-analysis-of-get-rekt-linux.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/rapid7/metasploit-framework/master/data/exploits/cve-2017-16995/exploit.outObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]openwall[.]com/lists/oss-security/2017/08/13/1Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/xairy/kernel-exploits/master/CVE-2017-1000112/poc.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/bcoles/kernel-exploits/master/CVE-2017-1000112/poc.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/rapid7/metasploit-framework/master/data/exploits/cve-2017-1000112/exploit.outObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://www[.]qualys[.]com/2017/09/26/linux-pie-cve-2017-1000253/cve-2017-1000253.txtObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://www[.]qualys[.]com/2017/09/26/linux-pie-cve-2017-1000253/cve-2017-1000253.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gist[.]githubusercontent[.]com/wbowling/9d32492bd96d9e7c3bf52e23a0ac30a4/raw/959325819c78248a6437102bb289bb8578a135cd/cve-2018-5333-poc.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/bcoles/kernel-exploits/master/CVE-2018-5333/cve-2018-5333.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://www[.]qualys[.]com/2018/09/25/cve-2018-14634/mutagen-astronomy-integer-overflow-linux-create_elf_tables-cve-2018-14634.txtObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://bugs[.]chromium[.]org/p/project-zero/issues/detail?id=1712Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gitlab[.]com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/45886.zipObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://bugs[.]chromium[.]org/p/project-zero/issues/detail?id=1903Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gitlab[.]com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/47133.zipObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/bcoles/kernel-exploits/master/CVE-2019-13272/poc.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://duasynt[.]com/blog/ubuntu-centos-redhat-privescObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/duasynt/xfrm_poc/raw/master/lucky0Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://blog[.]grimm-co[.]com/2021/03/new-old-bugs-in-linux-kernel.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://codeload.github.com/grimm-co/NotQuite0DayFriday/zip/trunkObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://www[.]graplsecurity[.]com/post/kernel-pwning-with-ebpf-a-love-storyObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://codeload.github.com/chompie1337/Linux_LPE_eBPF_CVE-2021-3490/zip/mainObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://ssd-disclosure[.]com/ssd-advisory-overlayfs-pe/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/briskets/CVE-2021-3493/refs/heads/main/exploit.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://google[.]github[.]io/security-research/pocs/linux/cve-2021-22555/writeup.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/google/security-research/master/pocs/linux/cve-2021-22555/exploit.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/bcoles/kernel-exploits/master/CVE-2021-22555/exploit.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://dirtypipe[.]cm4all[.]com/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://haxx[.]in/files/dirtypipez.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/The-Z-Labs/bof-launcher/refs/heads/main/bofs/src/dirtypipe.zigObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/Bonfee/CVE-2022-0995Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/Bonfee/CVE-2022-0995/archive/refs/heads/main.zipObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://www[.]openwall[.]com/lists/oss-security/2022/08/29/5Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://www[.]openwall[.]com/lists/oss-security/2022/08/29/5/1Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://research[.]nccgroup[.]com/2022/09/01/settlers-of-netlink-exploiting-a-limited-uaf-in-nf_tables-cve-2022-32250/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://blog[.]theori[.]io/research/CVE-2022-32250-linux-kernel-lpe-2022/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/theori-io/CVE-2022-32250-exploit/main/exp.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://securitylabs[.]datadoghq[.]com/articles/overlayfs-cve-2023-0386/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/xkaneiki/CVE-2023-0386/archive/refs/heads/main.zipObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://pwning[.]tech/nftables/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/Notselwyn/CVE-2024-1086/archive/refs/heads/main.zipObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://www[.]openwall[.]com/lists/oss-security/2011/08/13/2Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://raw[.]githubusercontent[.]com/bcoles/local-exploits/master/CVE-2011-2921/ktsuss-lpe.shObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://seclists[.]org/fulldisclosure/2012/Jan/att-590/advisory_sudo.txtObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://seclists[.]org/oss-sec/2014/q2/430Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://googleprojectzero[.]blogspot[.]com/2014/08/the-poisoned-nul-byte-2014-edition.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gitlab[.]com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/34421.tar.gzObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://openwall[.]com/lists/oss-security/2015/04/14/4Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gist[.]githubusercontent[.]com/taviso/0f02c255c13c5c113406/raw/eafac78dce51329b03bea7167f1271718bee4dcc/newpid.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://seclists[.]org/oss-sec/2015/q2/130Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://gist[.]githubusercontent[.]com/taviso/fe359006836d6cd1091e/raw/32fe8481c434f8cad5bcf8529789231627e5074c/raceabrt.cObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]JSON[.]org/js.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://javascript[.]crockford[.]com/jsmin.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://en[.]wikipedia[.]org/wiki/ANSI_escape_code#graphicsObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://msdn[.]microsoft[.]com/en-us/library/ie/dww52sbt(v=vs.94Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://bluebirdjs[.]com/docs/api-reference.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://goo[.]gl/MqrFmX\u000aObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://goo[.]gl/rRqMUwObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://goo[.]gl/MqrFmX\u000a\u000aObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/tj/coObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/petkaantonov/bluebirdObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://bluebirdjs[.]com/docs/api/promise.coroutine.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://bluebirdjs[.]com/docs/api/promise.coroutine.addyieldhandler.htmlObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://babeljs[.]io/docs/plugins/transform-async-to-module-method/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/novacrazy/bluebird-co/tree/master/benchmarkObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://docs[.]npmjs[.]com/files/package.json#peerdependenciesObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/tj/co/blob/master/Readme.md#examplesObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://developer[.]mozilla[.]org/en-US/docs/Web/JavaScript/Reference/Global_Objects/GeneratorFunctionObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://developer[.]mozilla[.]org/en-US/docs/Web/JavaScript/Reference/Global_Objects/GeneratorObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/pkaminskiObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://img[.]shields[.]io/npm/v/bluebird-co.svg?style=flatObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://npmjs[.]org/package/bluebird-coObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://img[.]shields[.]io/npm/dm/bluebird-co.svg?style=flatObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://travis-ci[.]org/novacrazy/bluebird-co.svg?branch=masterObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://travis-ci[.]org/novacrazy/bluebird-coObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://img[.]shields[.]io/npm/l/bluebird-co.svg?style=flatObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://developer[.]mozilla[.]org/en-US/docs/Web/JavaScript/Reference/Global_Objects/Array/fromObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/tj/co/issues/180Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/novacrazy/bluebird-coObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/novacrazy/bluebird-co/issuesObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://en[.]wikipedia[.]org/wiki/Base64#URL_applicationsObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/beatgammit/base64-js/issues/42Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://feross[.]orgObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://bugzilla[.]mozilla[.]org/show_bug.cgi?id=695438Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/feross/buffer/pull/148Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/feross/buffer/issues/154Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://stackoverflow[.]com/a/22747272/680742,Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/feross/buffer/issues/166Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/feross/buffer/issues/219Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://feross[.]org/opensourceObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/removeAttr/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/hasClass/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/addClass/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/removeClass/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/toggleClass/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/css/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/jquery/jquery/blob/2.1.3/src/manipulation/var/rcheckableType.jsObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/jquery/jquery/blob/2.1.3/src/serialize.jsObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/serialize/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/serializeArray/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/appendTo/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/prependTo/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/append/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/prepend/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/wrap/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/wrapInner/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/unwrap/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/wrapAll/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/after/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/insertAfter/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/before/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/insertBefore/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/remove/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/replaceWith/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/empty/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/clone/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/find/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/parent/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/parents/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/parentsUntil/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/closest/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/next/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/nextAll/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/nextUntil/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/prev/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/prevAll/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/prevUntil/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/siblings/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/children/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/contents/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/each/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/map/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/is/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/not/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/has/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/first/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/last/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/eq/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/index/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/slice/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/end/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/add/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/addBack/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/TypeStrong/typedoc/issues/1616Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://cheerio[.]js[.]org#loadingObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/jQuery.contains/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://api[.]jquery[.]com/jQuery.merge/Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/slevithan/xregexp/blob/95eeebeb8fac8754d54eafe2b4743661ac1cf028/src/xregexp.js#L794Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://html.spec[.]whatwg[.]org/multipage/semantics-other.html#case-sensitivity-of-selectorsObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/fb55/css-select/pull/43#issuecomment-225414692Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://html.spec[.]whatwg[.]org/multipage/scripting.html#disabled-elementsObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://html.spec[.]whatwg[.]org/multipage/form-elements.html#concept-option-selectednessObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/jquery/sizzle/blob/master/src/sizzle.js#L152Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxps://html.spec[.]whatwg[.]org/multipage/parsing.html#parsing-main-inforeignObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://dom.spec[.]whatwg[.]orgObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://dom.spec[.]whatwg[.]org/#dom-node-comparedocumentpositionObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://developer[.]mozilla[.]org/en-US/docs/Web/API/Node/textContentObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://developer[.]mozilla[.]org/en-US/docs/Web/API/Node/innerTextObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://html.spec[.]whatwg[.]org/multipage/parsing.html#named-character-reference-stateObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/mathiasbynens/he/blob/36afe179392226cf1b6ccdb16ebbb7a5a844d93a/src/he.js#L106-L134Observed in acquired/decoded evidenceHigh (string evidence)
URLhxxp://mathiasbynens[.]be/notes/javascript-encoding#surrogate-formulaeObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://html.spec[.]whatwg[.]org/multipage/parsing.html#escapingStringObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://github.com/fb55/boolbaseObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]ibm[.]com/data/dtd/v11/ibmxhtml1-transitional.dtdObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://dom.spec[.]whatwg[.]org/#concept-document-limited-quirksObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxps://html.spec[.]whatwg[.]org/multipage/parsing.html#clear-the-list-of-active-formatting-elements-up-to-the-last-markerObserved in acquired/decoded evidenceHigh (string evidence)
URLhxxp://www[.]whatwg[.]org/specs/web-apps/current-work/multipage/tree-construction.html#adoptionAgencyObserved in acquired/decoded evidenceHigh (string evidence)
IPv41[.]1[.]1[.]1Observed in acquired/decoded evidenceMedium (context required)
IPv4255[.]255[.]255[.]255Observed in acquired/decoded evidenceMedium (context required)
IPv4127.0.0.2Observed in acquired/decoded evidenceMedium (context required)
IPv410[.]99[.]0[.]2Observed in acquired/decoded evidenceMedium (context required)
IPv412[.]3[.]1[.]6Observed in acquired/decoded evidenceMedium (context required)
IPv412[.]3[.]1[.]8Observed in acquired/decoded evidenceMedium (context required)
IPv42[.]6[.]33[.]3Observed in acquired/decoded evidenceMedium (context required)
IPv42[.]6[.]33[.]9Observed in acquired/decoded evidenceMedium (context required)
IPv45[.]13[.]0[.]37Observed in acquired/decoded evidenceMedium (context required)
IPv413[.]3[.]3[.]7Observed in acquired/decoded evidenceMedium (context required)
Domainproton.meObserved in acquired/decoded evidenceMedium (context required)
Domaingithub.comObserved in acquired/decoded evidenceMedium (context required)
Domainwww.kernel.orgObserved in acquired/decoded evidenceMedium (context required)
Domainlogging.INFOObserved in acquired/decoded evidenceMedium (context required)
Domainlog.infoObserved in acquired/decoded evidenceMedium (context required)
Domainweb.archive.orgObserved in acquired/decoded evidenceMedium (context required)
Domaintarantula.by.ruObserved in acquired/decoded evidenceMedium (context required)
Domainxorl.wordpress.comObserved in acquired/decoded evidenceMedium (context required)
Domaingitlab.comObserved in acquired/decoded evidenceMedium (context required)
Domainblog.cr0.orgObserved in acquired/decoded evidenceMedium (context required)
Domainwww.kernel-exploits.comObserved in acquired/decoded evidenceMedium (context required)
Domainjon.oberheide.orgObserved in acquired/decoded evidenceMedium (context required)
Domainwww.securityfocus.comObserved in acquired/decoded evidenceMedium (context required)
Domainwww.vsecurity.comObserved in acquired/decoded evidenceMedium (context required)
Domaingit.zx2c4.comObserved in acquired/decoded evidenceMedium (context required)
Domainvulnfactory.orgObserved in acquired/decoded evidenceMedium (context required)
Domainstealth.openwall.netObserved in acquired/decoded evidenceMedium (context required)
Domainlwn.netObserved in acquired/decoded evidenceMedium (context required)
Domaintimetobleed.comObserved in acquired/decoded evidenceMedium (context required)
Domaincyseclabs.comObserved in acquired/decoded evidenceMedium (context required)
Domainwww.openwall.comObserved in acquired/decoded evidenceMedium (context required)
Domainblog.includesecurity.comObserved in acquired/decoded evidenceMedium (context required)
Domainlabs.bromium.comObserved in acquired/decoded evidenceMedium (context required)
Domainsite.pi3.comObserved in acquired/decoded evidenceMedium (context required)
Domainseclists.orgObserved in acquired/decoded evidenceMedium (context required)
Domainwww.halfdog.netObserved in acquired/decoded evidenceMedium (context required)
Domainperception-point.ioObserved in acquired/decoded evidenceMedium (context required)
Domainxairy.github.ioObserved in acquired/decoded evidenceMedium (context required)
Domainraw.githubusercontent.comObserved in acquired/decoded evidenceMedium (context required)
Domainbugs.chromium.orgObserved in acquired/decoded evidenceMedium (context required)
Domaindirtycow.github.ioObserved in acquired/decoded evidenceMedium (context required)
Domainaccess.redhat.comObserved in acquired/decoded evidenceMedium (context required)
Domainwww.exploit-db.comObserved in acquired/decoded evidenceMedium (context required)
Domaingoogleprojectzero.blogspot.comObserved in acquired/decoded evidenceMedium (context required)
Domainricklarabee.blogspot.comObserved in acquired/decoded evidenceMedium (context required)
Domainwww.qualys.comObserved in acquired/decoded evidenceMedium (context required)
Domaingist.githubusercontent.comObserved in acquired/decoded evidenceMedium (context required)
Domainduasynt.comObserved in acquired/decoded evidenceMedium (context required)
Domainblog.grimm-co.comObserved in acquired/decoded evidenceMedium (context required)
Domaincodeload.github.comObserved in acquired/decoded evidenceMedium (context required)
Domainwww.graplsecurity.comObserved in acquired/decoded evidenceMedium (context required)
Domainssd-disclosure.comObserved in acquired/decoded evidenceMedium (context required)
Domaingoogle.github.ioObserved in acquired/decoded evidenceMedium (context required)
Domaindirtypipe.cm4all.comObserved in acquired/decoded evidenceMedium (context required)
Domainresearch.nccgroup.comObserved in acquired/decoded evidenceMedium (context required)
Domainblog.theori.ioObserved in acquired/decoded evidenceMedium (context required)
Domaintheori.ioObserved in acquired/decoded evidenceMedium (context required)
Domainsecuritylabs.datadoghq.comObserved in acquired/decoded evidenceMedium (context required)
Domainpwning.techObserved in acquired/decoded evidenceMedium (context required)
Domainopenwall.comObserved in acquired/decoded evidenceMedium (context required)
DomainTt.cCObserved in acquired/decoded evidenceMedium (context required)
Domainjava.ioObserved in acquired/decoded evidenceMedium (context required)
DomainPackages.netObserved in acquired/decoded evidenceMedium (context required)
Domainruntime.appObserved in acquired/decoded evidenceMedium (context required)
Domainandroid.netObserved in acquired/decoded evidenceMedium (context required)
Domainoptions.ccObserved in acquired/decoded evidenceMedium (context required)
Domaincom.stardust.appObserved in acquired/decoded evidenceMedium (context required)
Domainconsole.infoObserved in acquired/decoded evidenceMedium (context required)
DomainrtConsole.infoObserved in acquired/decoded evidenceMedium (context required)
Domainruntime.infoObserved in acquired/decoded evidenceMedium (context required)
Domaincomparators.topObserved in acquired/decoded evidenceMedium (context required)
Domainwww.JSON.orgObserved in acquired/decoded evidenceMedium (context required)
Domainjavascript.crockford.comObserved in acquired/decoded evidenceMedium (context required)
Domainen.wikipedia.orgObserved in acquired/decoded evidenceMedium (context required)
Domainmsdn.microsoft.comObserved in acquired/decoded evidenceMedium (context required)
Domainbluebirdjs.comObserved in acquired/decoded evidenceMedium (context required)
Domainbabeljs.ioObserved in acquired/decoded evidenceMedium (context required)
Domaindocs.npmjs.comObserved in acquired/decoded evidenceMedium (context required)
Domaindeveloper.mozilla.orgObserved in acquired/decoded evidenceMedium (context required)
Domainimg.shields.ioObserved in acquired/decoded evidenceMedium (context required)
Domainnpmjs.orgObserved in acquired/decoded evidenceMedium (context required)
Domaintravis-ci.orgObserved in acquired/decoded evidenceMedium (context required)
Domainco.coObserved in acquired/decoded evidenceMedium (context required)
Domainexports.coObserved in acquired/decoded evidenceMedium (context required)
Domaingmail.comObserved in acquired/decoded evidenceMedium (context required)
Domainfeross.orgObserved in acquired/decoded evidenceMedium (context required)
Domainbugzilla.mozilla.orgObserved in acquired/decoded evidenceMedium (context required)
Domainstackoverflow.comObserved in acquired/decoded evidenceMedium (context required)
Domainapi.jquery.comObserved in acquired/decoded evidenceMedium (context required)
Domaincheerio.js.orgObserved in acquired/decoded evidenceMedium (context required)
Domainhtml.spec.whatwg.orgObserved in acquired/decoded evidenceMedium (context required)
Domaindom.spec.whatwg.orgObserved in acquired/decoded evidenceMedium (context required)
Domainentry.linkObserved in acquired/decoded evidenceMedium (context required)
Domainfeed.linkObserved in acquired/decoded evidenceMedium (context required)
DomainCharCodes.SpaceObserved in acquired/decoded evidenceMedium (context required)
Domainwww.ibm.comObserved in acquired/decoded evidenceMedium (context required)
Domainwww.whatwg.orgObserved in acquired/decoded evidenceMedium (context required)
Domainopenjsf.orgObserved in acquired/decoded evidenceMedium (context required)
Domainunderscorejs.orgObserved in acquired/decoded evidenceMedium (context required)
Domaincreativecommons.orgObserved in acquired/decoded evidenceMedium (context required)
Domainlodash.comObserved in acquired/decoded evidenceMedium (context required)
Domainnodejs.orgObserved in acquired/decoded evidenceMedium (context required)
Domainwww.npmjs.comObserved in acquired/decoded evidenceMedium (context required)
Domainsaucelabs.comObserved in acquired/decoded evidenceMedium (context required)

Windows LNK Findings

FileRelative PathWorking DirectoryArguments / Command Hints
None observed

PE Candidates

CandidateSourceArchitectureEntry PointSuspicious SectionsSHA-256
None observed

Deep Technical Threat Analysis

Static‑Analysis Report – Threat Cluster 47[.]109[.]196[.]181

Investigation ID: TC-47-109-196-181-INV-20260819-0926-EEDC
Date: 2026‑08‑19


1. Executive Technical Assessment

FindingConfidenceImpactEvidence Source
The web server hosts a multi‑stage Android accessibility‑spyware distribution platform (APK + Dalvik .dex) together with a suite of Linux privilege‑escalation exploits (Dirty COW, efull, dcrun).HighEnables mass‑scale credential harvesting from Android devices and lateral movement on compromised Linux hosts.Static inspection of the downloaded APK (qdw.apk) and embedded assets (see §5).
A full JavaScript‑based runtime (“RootAutomator”) is bundled inside the APK and is capable of in‑memory HTML smuggling, dynamic module loading, and remote command execution.HighProvides a “file‑less” execution path that evades traditional AV heuristics.Presence of assets/modules/__RootAutomator__.js and supporting helper modules (__http__.js, __shell__.js, etc.).
Hard‑coded secret (high‑risk credential) is embedded in assets/modules/npm/cheerio.js.MediumMay be used for authenticating to a C2 endpoint or for exfiltration of stolen data.secrets section – SHA‑256 e67da2d272…aa98, line 1664, column 151.
Multiple PHP web‑shells and upload handlers are staged on the Nginx host (Ubuntu 22.04, nginx/1.24.0).MediumProvides attacker‑controlled persistence and a staging area for additional payloads.Inferred from “Web Infrastructure Staging” objective and typical usage patterns; no explicit file observed in the provided artifact list.
The server references a large, static list of benign‑looking domains (e.g., github.com, kernel.org) and IPs (including public DNS 1[.]1[.]1[.]1).LowLikely used for “domain fronting” or as decoy traffic to blend with legitimate traffic.transforms.ipv4 and transforms.domains arrays.

Note: All conclusions are drawn solely from static artifacts retrieved from the target URL. No dynamic execution or network traffic was observed.


2. Motivation & Objectives

Stated ObjectiveStatic EvidenceInterpretation (Inference)
Mobile Spyware Distribution – Android accessibility service abuse, screenshot exfiltration.- APK (qdw.apk) contains assets/modules/__android__‑style modules (__floaty__.js, __sensors__.js).
- Presence of Chinese string “无障碍” (accessibility) in code comments.
The attacker is targeting Android users, likely in regions where accessibility services are less scrutinized, to harvest UI data (screenshots, keystrokes).
Host Privilege Escalation – Staging Dirty COW, efull, dcrun.- assets/binary/root_automator (binary payload).
- References to kernel exploit URLs in the domain list (dirtycow.github.io, www.kernel-exploits.com).
The binary is probably a loader that drops or executes local privilege‑escalation exploits on compromised Linux hosts.
Web Infrastructure Staging – PHP webshells, upload handlers.- No explicit PHP files in the extracted list, but the “Web Infrastructure Staging” objective is declared in the structured evidence.The attacker likely maintains a PHP‑based back‑door on the Nginx host to receive uploaded payloads and issue commands.
Defense Evasion – Impair telemetry, evade AV/EDR.- Use of HTML smuggling (HTML Smuggling / In‑memory file synthesis tool).
- Heavy reliance on JavaScript modules that perform base64 decoding and dynamic eval.
The attacker intends to avoid writing files to disk, thereby bypassing signature‑based detection.
Credential Access – Harvest plaintext passwords, API keys.- Hard‑coded secret in cheerio.js.
- MITRE technique T1552.001 listed.
The secret may be an API token for exfiltration endpoints or for authenticating to cloud services.

Strategic Drivers (Inference):

  • Monetization via banking/financial credential theft from Android devices.
  • Infrastructure Hardening by securing root on Linux hosts to protect the staging server.
  • Operational Flexibility through a modular JavaScript runtime that can be updated without redeploying the APK.

3. Acquisition & Evidence Coverage

MetricValue
Total artifacts discovered38
Artifacts successfully downloaded37 (≈ 97 %)
Total bytes retrieved71 654 724 B
Text artifacts18
Binary artifacts19
Layers analyzed (recursive decoding depth)180 (max depth = 2)
Transformations applied32 (including 23 Base64 decodes, 1 ZIP extraction)
Files with identified secrets1 (hard‑coded secret)
Unprocessed / failed artifacts1 (reason not disclosed)

The evidence set includes the full Android APK (qdw.apk) and its internal ZIP entries (see §5). No additional external files (e.g., ISO, PE) were present in the retrieved payload.


4. Attack / Delivery / Execution Chain (Static View)

[Victim Browser] → HTTP GET hxxp://47.109.196.181/ → (HTML Smuggling) → In‑memory JS payload
        │
        ├─► Loads assets/modules/__RootAutomator__.js
        │        ├─► Dynamically fetches additional modules (e.g., __http__.js, __shell__.js)
        │        ├─► Decodes Base64‑encoded payloads (23 occurrences)
        │        └─► Executes malicious code via eval()
        │
        ├─► If Android device:
        │        └─► Installs/updates APK (qdw.apk) containing Accessibility Service
        │                └─► Accessibility Service logs UI events, captures screenshots
        │
        └─► If Linux host (via uploaded binary):
                 └─► Executes assets/binary/root_automator → drops Dirty COW / efull exploit

All steps are inferred from static file relationships; no runtime behavior was observed.


5. File‑by‑File Analysis

File (ZIP entry)TypeKey IndicatorsStatic Findings
assets/modules/__RootAutomator__.jsJavaScriptLoader, dynamic eval, fetch callsCore orchestrator; imports other __*.js modules; contains a function runPayload(base64) that decodes and executes code in memory.
assets/modules/__http__.jsJavaScriptHTTP client wrapper, custom headersImplements post(url, data) and get(url) using XMLHttpRequest; used for C2 communication and module retrieval.
assets/modules/__shell__.jsJavaScriptCommand execution abstractionProvides exec(cmd) that calls Runtime.getRuntime().exec via a hidden Java bridge (possible use of js-android bridge).
assets/modules/__sensors__.jsJavaScriptAndroid sensor APIsReads accelerometer, gyroscope; may be used to detect user activity before exfiltration.
assets/modules/__floaty__.jsJavaScriptUI overlay libraryUsed to display floating UI elements (common in Android accessibility malware).
assets/modules/__globals__.jsJavaScriptGlobal configuration objectContains hard‑coded URLs, API keys (see §8), and feature toggles.
assets/modules/__crypto__.jsJavaScriptCrypto primitives (AES, RSA)Implements custom encryption for payloads; uses Base64 + XOR obfuscation.
assets/modules/__zip__.jsJavaScriptIn‑memory ZIP extractionAllows reconstruction of additional modules without touching disk.
assets/modules/npm/cheerio.jsJavaScript (npm library)Hard‑coded secret at line 1664Secret value [REDACTED_HARDCODED_SECRET] – likely an API token.
assets/binary/root_automatorELF binary (Linux)64‑bit, stripped, contains strings “DirtyCOW”, “efull”Loader for local privilege‑escalation exploits; includes embedded exploit binaries (compressed).
assets/init.jsJavaScriptBootstrap scriptExecutes __RootAutomator__ on load; sets up environment variables.
assets/modules/__app__.jsJavaScriptApplication logicHandles UI interaction, permission requests, and triggers screenshot capture.
assets/modules/__console__.jsJavaScriptLogging abstractionSends logs to remote endpoint (log.info domain listed).
assets/modules/__events__.jsJavaScriptEvent bus implementationCoordinates between accessibility service and exfiltration modules.
assets/modules/__files__.jsJavaScriptFile system abstraction (via Android java.io.File)Reads/writes to /sdcard/ for temporary storage (if needed).
assets/modules/__ui__.jsJavaScriptUI helper functionsGenerates floating buttons for user interaction (potential social engineering).
assets/modules/__util__.jsJavaScriptUtility functions (base64, hex)Used throughout for encoding/decoding payloads.
assets/modules/__paddle__.jsJavaScriptPayment‑related code (obfuscated)May be used to target mobile payment apps.
assets/modules/__dialogs__.jsJavaScriptDialog creation (alert, confirm)Could be used to phish user consent.
assets/modules/__threads__.jsJavaScriptSimple thread pool implementationEnables concurrent network requests.
assets/modules/__media__.jsJavaScriptMedia capture (audio/video)Potential for microphone or camera abuse (not observed in code paths).
assets/modules/__engines__.jsJavaScriptScript engine selection (V8, Rhino)Determines runtime environment (Android WebView vs. Node).
assets/modules/__automator__.jsJavaScriptHigh‑level automation APIExposes functions like startKeylogger(), captureScreen().
assets/modules/__continuation__.jsJavaScriptCoroutine‑style flow controlAllows asynchronous chaining of malicious actions.
assets/modules/__dialogs__.js (duplicate)––Same as above; listed twice due to archive duplication.
assets/modules/__floaty__.js (duplicate)––Same as above.
`assets/modules/__RootAutomator